The organization-backed repository has recent commits and a current release, but all five workflow actions are unpinned and one person made every recent commit. The MIT license, release notes, and complete source tree improve transparency.
72%
Total Score
83
100
93
67
One maintainer made all ten commits in the last three months, creating a meaningful continuity risk. Organization backing partly compensates because maintenance can potentially be handed off.
The project uses Make and Composer, but no security-scanning tools were detected, leaving a modest transparency and hygiene gap.
The repository has no security policy, so the process for reporting and handling vulnerabilities is unclear.
The workflow audit completed cleanly with no untrusted checkouts, injection findings, or excessive top-level permissions. However, all five analyzed action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.